This IP address has been reported a total of
67
times from
51 distinct
sources.
146.103.97.119 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 21
reports;
Germany
with 12
reports;
France
with 7
reports.
The most common categories in these recent reports were:
Port Scan
34
times;
Brute-Force
22
times;
Web App Attack
18
times;
Hacking
13
times;
SSH
13
times;
Other
12
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-09-28T20:29:54Z - Recognized attacks\bad behavior from IP address 146.103.97.119 on port 443\80 ...
show more2026-09-28T20:29:54Z - Recognized attacks\bad behavior from IP address 146.103.97.119 on port 443\80 (9 daily hits): client denied by server configuration
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Web App Attack
{"ClientAddr":"146.103.97.119:43650","ClientHost":"146.103.97.119","ClientPort":"43650","ClientUsern ...
show more{"ClientAddr":"146.103.97.119:43650","ClientHost":"146.103.97.119","ClientPort":"43650","ClientUsername":"-","DownstreamContentSize":19,"DownstreamStatus":404,"Duration":64750,"GzipRatio":0,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":64750,"RequestAddr":"148.253.213.233:443","RequestContentSize":0,"RequestCount":1827939,"RequestHost":"148.253.213.233","RequestMethod":"POST","RequestPath":"/index.php?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input","RequestPort":"443","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"StartLocal":"2026-09-28T19:56:57.070655098Z","StartUTC":"2026-09-28T19:56:57.070655098Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"websecure","level":"info","msg":"","time":"2026-09-28T19:56:57Z"}
{"ClientAddr":"146.103.97.119:43650","ClientHost":"146.103.97.119","ClientPort":"43650","ClientUsername":"-","DownstreamContentSize":19,"DownstreamStatus":404,"Duration":46023,"GzipR
...
show less
2026-09-28T21:30:32.359406+02:00 francesco sshd[2701576]: Failed password for root from 146.103.97.1 ...
show more2026-09-28T21:30:32.359406+02:00 francesco sshd[2701576]: Failed password for root from 146.103.97.119 port 44058 ssh2
2026-09-28T21:36:12.522829+02:00 francesco sshd[2732718]: Connection from 146.103.97.119 port 31764 on 95.216.24.245 port 22 rdomain ""
2026-09-28T21:36:18.605563+02:00 francesco sshd[2732718]: Invalid user user from 146.103.97.119 port 31764
2026-09-28T21:36:18.611514+02:00 francesco sshd[2732718]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=146.103.97.119
2026-09-28T21:36:20.870906+02:00 francesco sshd[2732718]: Failed password for invalid user user from 146.103.97.119 port 31764 ssh2
...
show less
Blocked by UFW (TCP on 23)
Source port: 57564
TTL: 51
Packet length: 44
TOS: 0x00
This report (for ...
show moreBlocked by UFW (TCP on 23)
Source port: 57564
TTL: 51
Packet length: 44
TOS: 0x00
This report (for 146.103.97.119) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Sangfor NGAF detected 'web Vulnerability' activity from IP 146.103.97.119. Event type: Intrusion Pre ...
show moreSangfor NGAF detected 'web Vulnerability' activity from IP 146.103.97.119. Event type: Intrusion Prevention. Communication involved internal asset 192.168.89.35. Detection time: 2026-09-29 01:41:35. Activity was classified by the firewall security engine and logged for threat monitoring. Internal addresses in 222.165.225.0/24 were excluded from reporting.
show less
Sep 28 15:00:00 GMNH10459 sshd[1850123]: Invalid user user from 146.103.97.119 port 38619
Sep 28 15: ...
show moreSep 28 15:00:00 GMNH10459 sshd[1850123]: Invalid user user from 146.103.97.119 port 38619
Sep 28 15:00:00 GMNH10459 sshd[1850123]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=146.103.97.119
Sep 28 15:00:02 GMNH10459 sshd[1850123]: Failed password for invalid user user from 146.103.97.119 port 38619 ssh2
Sep 28 15:05:49 GMNH10459 sshd[1854260]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=146.103.97.119 user=root
Sep 28 15:05:50 GMNH10459 sshd[1854260]: Failed password for root from 146.103.97.119 port 27781 ssh2
...
show less
Brute-Force
SSH
Anonymous
Bot / scanning and/or hacking attempts: POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/. ...
show moreBot / scanning and/or hacking attempts: POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e
show less
2026-09-28T19:25:15.378422+02:00 meet sshd-session[25438]: Invalid user admin from 146.103.97.119 po ...
show more2026-09-28T19:25:15.378422+02:00 meet sshd-session[25438]: Invalid user admin from 146.103.97.119 port 55578
...
show less